Critical—9 Vulnerabilities in Orthanc DICOM Servers Threaten Medical Data Integrity
ID: 568fe7c0-a1ba-5793-ba83-fe662f0093b8
STIX ID: report--568fe7c0-a1ba-5793-ba83-fe662f0093b8
Feed Name: securityonline.info
Orthanc (≤1.12.10) contains nine critical vulnerabilities—notably CVE-2026-5438 (gzip decompression bomb), CVE-2026-5440 (unbounded Content-Length), and CVE-2026-5442/5443 (heap buffer overflows in image decoding)—that can crash servers, disclose heap-resident data (including private DICOM content), and under some conditions enable remote code execution. The advisory warns of persistent malicious DICOM content that may be stored and later re-triggered; recommended mitigations are immediate upgrade to Orthanc 1.12.11, limiting upload/processing exposure to trusted networks, and auditing configurations and deployment guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
